--- - branch: netbsd-7 date: Sat May 16 18:02:14 UTC 2015 files: - new: 1.17.22.2 old: 1.17.22.1 path: src/common/lib/libprop/prop_kern.c pathrev: src/common/lib/libprop/prop_kern.c@1.17.22.2 type: modified - new: 1.29.4.1 old: '1.29' path: src/common/lib/libprop/prop_object.c pathrev: src/common/lib/libprop/prop_object.c@1.29.4.1 type: modified - new: 1.31.12.1 old: '1.31' path: src/common/lib/libprop/prop_object_impl.h pathrev: src/common/lib/libprop/prop_object_impl.h@1.31.12.1 type: modified id: 20150516T180214Z.0947eb6d6a7094fa203b34e41fe618a1b4033b20 log: "Pull up following revision(s) (requested by christos in ticket #782):\n\tcommon/lib/libprop/prop_kern.c: revision 1.19\n\tcommon/lib/libprop/prop_object.c: revision 1.30\n\tcommon/lib/libprop/prop_object_impl.h: revision 1.32\nLimit size of xml buffer for userland requests (From Mateusz Kocielski)\n--\nDon't treat NUL (EOF) as SPACE. All the code that uses _PROP_ISSPACE() checks\nexplicitly for _PROP_EOF() anyway, and this can be abused to cause run beyond\nthe end of buffer DoS (Mateusz Kocielski)\n--\nNow that _PROP_ISSPACE does not include the EOF check, put the check for\nEOF inside the loop. Also fix another unbounded loop that did not check for\nEOF. From Mateusz Kocielski\n" module: src subject: 'CVS commit: [netbsd-7] src/common/lib/libprop' unixtime: '1431799334' user: snj